Solved! Use APPLETS.EXE (Trojan Crypt) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

APPLETS.EXE – Trojan Crypt removal

File MD5 Virus Alias
APPLETS.EXE 0de74ef75076f6ca2073acea2dc29df3 Trojan Crypt
APPLETS.EXE 0de74ef75076f6ca2073acea2dc29df3 Trojan Generic
APPLETS.EXE 0de74ef75076f6ca2073acea2dc29df3 Trojan Xema
APPLETS.EXE 0de74ef75076f6ca2073acea2dc29df3 Trojan Comame
APPLETS.EXE 0de74ef75076f6ca2073acea2dc29df3 Trojan PAM
APPLETS.EXE 0de74ef75076f6ca2073acea2dc29df3 Trojan Agent

APPLETS.EXE size: 187994 bytes
APPLETS.EXE hash: 0DE74EF75076F6CA2073ACEA2DC29DF3

Created files:

C:\Windows\Help\intret.cnt
C:\Windows\Syssrc32.exe
C:\Windows\System\applets.exe
C:\Windows\System\Explorer.exe
C:\Windows\System\fndfst32.exe
C:\Windows\System\mplayerw.exe
C:\Windows\System\Sysexp32.exe
%Temp%\1D87B2.dmp

Autostart registry keys:

HKLM\Software\Classes\txtfile\shell\open\command\Explore: %SystemRoot%\System32\NOTEPAD.EXE %1
HKLM\Software\Classes\txtfile\shell\open\command : C:\Windows\System\Sysexp32.exe %1
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\System applets: C:\Windows\System\applets.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Syssrc32: C:\Windows\Syssrc32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\fndfst32: C:\Windows\System\fndfst32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Explorer Shell: C:\Windows\System\Explorer.exe

Detected by UnHackMe:

APPLETS.EXE
Default location: %WinDir%\SYSTEM\APPLETS.EXE

Dropper information:
MD5: 64092b65d2cd79275aa4f8354c7b99f0
File size: 184918 bytes

Leave a Reply